AutoDefense: Reinforcement Learning Based Autoreactive Defense Against Network Attacks

AutoDefense: Reinforcement Learning Based Autoreactive Defense Against Network Attacks
复制标题

DOI:
10.1109/cns56114.2022.9947232
复制
发表时间:
2022-10
期刊:
2022 IEEE Conference on Communications and Network Security (CNS)
影响因子:
--
通讯作者:
Yu Mi;David A. Mohaisen;An Wang
Yu Mi;David A. Mohaisen;An Wang
中科院分区:
其他
文献类型:
--
作者:
Yu Mi;David A. Mohaisen;An Wang

文献摘要

相似文献

由于软件定义网络(SDN)技术提供的可编程性和可见性,可以在网络攻击上执行更灵活和复杂的功能。然而,准确识别攻击流量以缓解攻击是一个挑战。大多数现有的解决方案利用流量特性来实现这一目标。最近的攻击特征变得更加复杂,与合法流量难以区分。在本文中,我们提出了AutoDefense,这是一种新的框架,它利用强化学习技术,根据从数据平面收集的信号动态自适应地部署防御策略。虽然我们试图实现与现有努力相同的目标,即攻击者控制的网络/服务器资源应该受到限制,但我们允许更多合法的流量进入网络,而不是在攻击发生时放弃带宽。通过评估,我们证明AutoDefense可以减少39%的攻击流量,并允许网络中的合法流量增加48.6%。AutoDefense还将长尾延迟流的平均流完成时间提高了42.7%。
Attributed to the programmability and visibility provided by Software Defined Network (SDN) technologies, more flexible and complex functions can be performed on network at-tacks. However, identifying the attack traffic accurately for attack mitigation is a challenge. Most existing solutions leverage traffic characteristics to achieve this goal. Recent attacks characteristics have become more complex and indistinguishable from legitimate traffic. In this paper, we propose AutoDefense, a novel frame-work that leverages reinforcement learning techniques to deploy defense policies dynamically and adaptively based on the signals collected from the data plane. While we seek to achieve the same goal with the existing efforts where the network/server resources the attackers control should be limited, we allow more legitimate flows to enter the network, rather than relinquish bandwidth when attacks happen. Through evaluations, we demonstrate that AutoDefense could reduce 39% of the attack traffic and allow 48.6 % more legitimate flows in the network. AutoDefense also improves the average flow completion time by 42.7% for the flows with a long tail latency.